Database/Control plane, storage & DevOps

HPE StoreOnce (authentication bypass): Unauthenticated attacker bypasses authentication on StoreOnce entirely, gaining
Impact
Unauthenticated attacker bypasses authentication on StoreOnce entirely, gaining full control of the backup appliance. Backup systems hold copies of everything and are a primary ransomware target - this is the bug that makes your recovery path attackable.
Who can reach it
Network access to the StoreOnce management interface. No credentials.
What to do
Upgrade StoreOnce Software per HPESBST04847 as a priority. Appliance upgrade with a service window. Verify backup immutability/retention-lock settings while you are there - authentication bypass plus mutable backups is the ransomware worst case.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.